REDHAT-BUG-1652194: Medium severity gnome keyring vulnerability
GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML elements) are not used.
References: https://bugs.launchpad.net/ubuntu/+source/gnome-keyring/+bug/1780365
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1652194?
The severity of REDHAT-BUG-1652194 is considered critical due to the potential for unauthorized access to sensitive login credentials.
How do I fix REDHAT-BUG-1652194?
To fix REDHAT-BUG-1652194, ensure that GNOME Keyring is updated to a version later than 3.28.2.
Who is affected by REDHAT-BUG-1652194?
Local users who have access to an unlocked GNOME Keyring 3.28.2 are affected by REDHAT-BUG-1652194.
What can an attacker do with REDHAT-BUG-1652194?
An attacker can retrieve sensitive login credentials via the Secret Service API if they have access to an unlocked keyring.
Is there a workaround for REDHAT-BUG-1652194?
A temporary workaround for REDHAT-BUG-1652194 is to lock the GNOME Keyring when not in use to prevent unauthorized access.